Is lexus.com legit?
Lexus.com is a highly trusted website, which is expected for such a prominent automotive brand. While it exhibits strong technical foundations and a long-standing online presence, minor improvements in transparency and legal documentation could make it even stronger.
Automotive average: 73/100 · based on 29 sites
Checked: April 18, 2026 at 8:13 AM UTC · Refresh
Is lexus.com a scam? Here's what we found.
The site's security setup is robust, featuring HSTS for secure connections, strong clickjacking protection, and a clean Google Web Risk report. The certificate transparency check was inconclusive but doesn't necessarily indicate a flaw.
With over 33 years online and registration through a reputable registrar like MarkMonitor, the domain's identity is exceptionally well-established and clearly belongs to Lexus, offering high confidence in who is behind the site.
The site boasts an excellent reputation, demonstrated by its clean DNS blacklist status and comprehensive 29-year history on the Web Archive, reinforcing its long-term, legitimate presence.
While the site has strong branding, the absence of easily accessible contact information and social media links on the homepage is a slight detractor for user-friendliness and direct engagement. For a major automotive brand, a more direct communication path would be expected.
The partial legal pages, specifically missing either a privacy policy or terms of service, are a notable concern for a company of this stature, as these documents are crucial for user trust and regulatory compliance.
The website's technical infrastructure is solid, with good DNS resolution, proper email authentication (SPF and DMARC), and a well-maintained sitemap, indicating a professional setup.
Signals Detected
This site has moderate global traffic
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1993-01-22T05:00:00Z (33 years, 8 months ago)
Registered through MarkMonitor Inc.
Expires in 644 days
DNSSEC status from WHOIS
crt.sh returned status 429
robots.txt has 5 directives and references a sitemap
Site maintains a proper sitemap with 569 indexed pages
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
No threats detected by Google Web Risk
Resolves to: 13.248.217.47, 76.223.71.125
Mail servers: mxa-001f1301.gslb.pphosted.com., mxb-001f1301.gslb.pphosted.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: pdns102.ultradns.com., pdns102.ultradns.net., pdns102.ultradns.org., ns1.toyota.com., pdns102.ultradns.biz.
Not found on any DNS blacklists
Valid certificate, expires in 172 days
Certificate issued by Amazon
Connection uses TLS 1.2
Site has custom branding and social media metadata
Website is live and responding
No obvious contact information found on homepage
Website is missing either privacy policy or terms of service
No social media links found on homepage
Earliest archive snapshot from 19961222
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.